IAPP-GDPR Web Banners-300x250-FINAL

Kirk J. Nahra, CIPP

The focus of healthcare privacy in 2007 will be on new enforcement issues, new opportunities and challenges related to the use of healthcare information. We also expect a renewed and continuing debate on whether new legislation is needed to address changes to the healthcare privacy environment.

Because of these developments, healthcare privacy clearly will be an important issue in the year ahead, not only for entities subject to the Health Insurance Portability and Accountability Act (HIPAA) rules, but also for the wide range of employers, vendors and others using healthcare information in new ways or pursuing new business opportunities tied to healthcare information or healthcare technology.

The HIPAA Enforcement Picture
Is this the year that HIPAA enforcement will become active? We may be seeing a perfect storm of pressures that will force enforcement action.

First, the political changes on Capitol Hill make clear that the current privacy enforcement structure will face intense scrutiny. Democratic lawmakers already have promised hearings and investigations into what the government is doing on enforcement, particularly for healthcare entities.

Second, we are starting to see other entities - beyond the Department of Health and Human Services (HHS) - getting into the enforcement picture for healthcare entities. For example, when Humana confronted two separate security breaches, it found itself facing charges from the North Dakota Insurance Commissioner, mandating credit monitoring services and payment of $50,000, to offset costs and expenses incurred by the department during its investigation.

In another case, unencrypted backup tapes and discs containing personal information on 365,000 patients of the Providence Health System were stolen from an employee's car. The Providence Health System reached a settlement recently with the Oregon Attorney General (who relied on the state Unlawful Trade Practices Act) requiring Providence to provide credit monitoring and credit restoration services, as well as enhance its security program.

Obviously, such state agencies are not the primary regulator of privacy and security practices for the healthcare industry. For example, in both the Humana and Providence situations above, one would think that, either the Office of Civil Rights (privacy) or the Centers for Medicare and Medicaid Services (security), would have been the relevant regulator for a security breach. Nonetheless, in 2007 and beyond, these "other" regulators may well be the main enforcers that companies have to worry about in the event of privacy or security problems. Their initiatives may, in turn, create pressure on HHS to take a more aggressive approach to privacy and security enforcement.

In addition, we have seen some signs that HHS will step up its enforcement efforts. Certainly, the agency's approach to date - particularly when the HIPAA Privacy Rule first went into effect - has been helpful in ensuring that appropriate information flow was not impeded. Moreover, despite the adverse publicity about HHS' lack of enforcement, many of the complaints that HHS has investigated have concerned (1) non-covered entities; (2) minor errors; or (3) no rule violation at all. So, the critics who highlight the large numbers of complaints without enforcement action may implicitly overstate the volume of actual privacy violations.

With all of that said, however, we predict that 2007 will see more enforcement of privacy and security obligations involving the healthcare industry, from both HHS and other regulators.

New Uses of Healthcare Information
Healthcare privacy also has been in the news recently, based on numerous developments affecting the use, disclosure and distribution of healthcare information. Several interrelated trends drive this complex problem. First, employer involvement in the management of their healthcare expenditures is on the rise. They are exploring new benefit options, designed to reduce overall expenditures and improve employee health. This has led to the need for more information, to evaluate how these new options are working. At the same time, employers (and many others) are interested in "wellness" activities - encouraging, incentivizing and even forcing employees into programs designed to improve overall health. Data clearly is needed to support these activities, if they are to be effective.

At the same time, medical research is expanding - and more research needs more data. Also, as medical research reaches further into the details of people's health, this information can be used in more and more ways - some seen as good, some bad, depending on one's perspective. So, the sensitivity of uses of medical data is increasing. Gaps in the HIPAA rules, and the increasing prominence of various international actors in the field of medical research, complicate an already complex regulatory structure.

In addition, the push toward electronic medical records and personal health records raises a wide variety of new and old issues. This movement aims to improve medical outcomes and decrease administrative costs in the healthcare industry. Achieving these goals requires appropriate privacy practices that maximize information availability while, at the same time, protecting patient privacy and assuring patients that their personal information is protected. This is an enormous challenge, one that involves analysis of existing laws, identification of current best practices, and a significant new debate about the appropriate means of protecting patient privacy. (Full disclosure -I co-chair a working group at the Department of Health and Human Services that is tasked with developing many of these practices.)

As this debate continues, the marketplace is moving ahead. Several large employers recently announced a new program to create personal health records for thousands of employees across the country. Almost simultaneously, two leading health insurance groups announced a joint program to develop compatible medical records for use by their customers. So, the healthcare industry - already at the forefront of privacy and security regulation - now is at the forefront of altering perceptions of how medical information should be used, prompting a new debate about the use and disclosure of medical information.

The electronic health records push and the encouragement of healthcare technology clearly are invigorating this debate about new uses of healthcare information. Key questions for this environment include:

  • What are the reasons for pushing a national healthcare information infrastructure?  
  • How do these new environments, particularly the creation of Regional Health Information Organizations (RHIOs) fit into the existing HIPAA structure?
  • Are new rules needed for this environment to drive our evaluation of how best to incorporate privacy and security principles into this new electronic environment?

These issues are being actively debated but few areas of clear consensus have emerged. Nevertheless, the business of healthcare technology is moving quickly, before the regulatory structure is defined. We may learn in 2007 whether the regulatory structure can catch up, or whether the relevant regulatory environment is so far behind that the marketplace will set most of the rules.

Renewed Policy Debate on Privacy Legislation
These new uses and the political changes on Capitol Hill also highlight a specific new question: Are new privacy rules needed for the healthcare industry? This debate addresses several key questions:

  • Are the HIPAA rules working effectively?
  • Does this new electronic technology environment require "something different" (i.e., new kinds of patient consent, increased security obligations, etc.)?
  • Do changes in the relevant players in a new technology environment mean that the HIPAA rules, even if appropriate for mainstream healthcare entities, do not work effectively for the non-covered entities and business associates who play a more prominent role in the health information networks?
  • As the uses of medical information change, will there need to be a new "overall" healthcare privacy law, one that protects healthcare information regardless of whether it is held by or created for a HIPAA-covered entity?

These issues are taking on increased visibility due to business developments and political change. They likely will be a focus of intense debate in 2007 and beyond. Any entity that uses, creates, discloses or maintains healthcare information needs to pay close attention to these developments.

Healthcare privacy - as a compliance issue - has been relatively quiet for a year or two. Now, companies are exploring new uses and disclosures of healthcare information, grumblings about enforcement are increasing, and we are seeing an expanding recognition of the limitations of the HIPAA rules as an effective approach to protecting overall healthcare privacy. So, we can anticipate an exciting year in the world of healthcare privacy in 2007.

Kirk J. Nahra is a Partner with Wiley Rein LLP in Washington, D.C., where he specializes in healthcare, privacy information security and counseling. He is chair of the firm's Privacy Practice and co-chair of its Healthcare Practice. Nahra is Editor of The Privacy Advisor. He may be reached at +202.719.7335 or by email at


This e-mail address is being protected from spam bots, you need JavaScript enabled to view it

© 2007 Wiley Rein LLP. Reprinted with permission, Privacy in Focus January 2007 ed. This is a publication of Wiley Rein LLP providing general news about recent legal developments and should not be construed as providing legal advice or legal opinions. You should consult an attorney for any specific legal questions.


If you want to comment on this post, you need to login.


Board of Directors

See the esteemed group of leaders shaping the future of the IAPP.

Contact Us

Need someone to talk to? We’re here for you.

IAPP Staff

Looking for someone specific? Visit the staff directory.

Learn more about the IAPP»

Daily Dashboard

The day’s top stories from around the world

Privacy Perspectives

Where the real conversations in privacy happen

The Privacy Advisor

Original reporting and feature articles on the latest privacy developments

Privacy Tracker

Alerts and legal analysis of legislative trends

Privacy Tech

Exploring the technology of privacy

Canada Dashboard Digest

A roundup of the top Canadian privacy news

Europe Data Protection Digest

A roundup of the top European data protection news

Asia-Pacific Dashboard Digest

A roundup of the top privacy news from the Asia-Pacific region

IAPP Westin Research Center

Original works. Groundbreaking research. Emerging scholars.

Advertise in IAPP Publications

Find out how to get your message in front the people you want to reach. Download a media kit now.

Get more News »

Find a KnowledgeNet Chapter Near You

Network and talk privacy at IAPP KnowledgeNet meetings, taking place worldwide.

Women Leading Privacy

Events, volunteer opportunities and more designed to help you give and get career support and expand your network.

IAPP Job Board

Looking for a new challenge, or need to hire your next privacy pro? The IAPP Job Board is the answer.

Join the Privacy List

Have ideas? Need advice? Subscribe to the Privacy List. It’s crowdsourcing, with an exceptional crowd.

Find more ways to Connect »

Find a Privacy Training Class

Two-day privacy training classes are held around the world. See the complete schedule now.

Online Privacy Training

Build your knowledge. The privacy know-how you need is just a click away.

The Training Post—Can’t-Miss Training Updates

Subscribe now to get the latest alerts on training opportunities around the world.

New Web Conferences Added!

See our list of upcoming web conferences. Just log on, listen in and learn!

Train Your Staff

Get your team up to speed on privacy by bringing IAPP training to your organization.

Learn more »

CIPP Certification

The global standard for the go-to person for privacy laws, regulations and frameworks

CIPM Certification

The first and only privacy certification for professionals who manage day-to-day operations

CIPT Certification

The industry benchmark for IT professionals worldwide to validate their knowledge of privacy requirements

Certify Your Staff

Find out how you can bring the world’s only globally recognized privacy certification to a group in your organization.

Learn more about IAPP certification »

Get Close-up

Looking for tools and info on a hot topic? Our close-up pages organize it for you in one easy-to-find place.

Where's Your DPA?

Our interactive DPA locator helps you find data protection authorities and summary of law by country.

IAPP Westin Research Center

See the latest original research from the IAPP Westin fellows.

Looking for Certification Study Resources?

Find out what you need to prepare for your exams

More Resources »

GDPR Comprehensive: Registration Open

New! Intensive two-day GDPR training led by the sharpest minds in the field. It's a can't-miss event.

The Congress Is Cancelled

The IAPP Europe Data Protection Congress 2015 is cancelled. Click through to learn more.

Sponsor an Event

Increase visibility for your organization—check out sponsorship opportunities today.

Exhibit at an Event

Put your brand in front of the largest gatherings of privacy pros in the world. Learn more.

More Conferences »

Become a Member

Start taking advantage of the many IAPP member benefits today

Corporate Members

See our list of high-profile corporate members—and find out why you should become one, too

Renew Your Membership

Don’t miss out for a minute—continue accessing your benefits

Join the IAPP»